NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
27409 | CVE-2015-6511 | Cross-site scripting (XSS) vulnerability in pfSense before 2.2.3 allows remote attackers to inject arbitrary web script or HTML via the server[] parameter to services_ntpd.php. | 2 | 4.3 | Medium | 2017-01-19 | 2015-08-19 | View | |
27665 | CVE-2015-6847 | The default configuration of EMC VPLEX GeoSynchrony 5.4 SP1 before P3 stores cleartext NAVISPHERE GUI passwords in a log file, which allows local users to obtain sensitive information by reading this file. | 2 | 2.1 | Low | 2017-01-19 | 2016-12-07 | View | |
27921 | CVE-2015-7238 | The Secondary server in Threat Intelligence Exchange (TIE) before 1.2.0 uses weak permissions for unspecified (1) configuration files and (2) installation logs, which allows local users to obtain sensitive information by reading the files. | 2 | 2.1 | Low | 2017-01-19 | 2015-09-22 | View | |
28177 | CVE-2015-7682 | Multiple SQL injection vulnerabilities in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allow remote administrators to execute arbitrary SQL commands via the (1) select_invitaion_code_bulk_option or (2) invi_del_id parameter in the pie-invitation-codes page to wp-admin/admin.php. | 2 | 6.5 | Medium | 2017-01-19 | 2015-10-19 | View | |
28433 | CVE-2015-8096 | Integer overflow in Google Picasa 3.9.140 Build 239 and Build 248 allows remote attackers to execute arbitrary code via unspecified vectors related to "phase one 0x412 tag," which triggers a heap-based buffer overflow. | 2 | 10 | High | 2017-01-19 | 2015-11-10 | View |
Page 1050 of 17672, showing 5 records out of 88360 total, starting on record 5246, ending on 5250